You currently have javascript disabled. Several functions may not work. Please re-enable javascript to access full functionality.

Register a free account to unlock additional features at BleepingComputer.com

Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Virtumonde Fixed But Left Registry Files

Hi, My computer was infected with the Virtumonde virus until I used Vundofix which found some files then had to use VirtumundoBeGone to clear the rest since I still got pop ups. It's been a day so far after using those programs and nothing comes up on adaware or Spy Bot except for cookies from places like advertising.com, fastclick and Doubleclick.net along with 3 files in the registry Spy Bot refers to as Virtumonde. I used Uniblue's RegistryBooster 2 to clean up but those 3 reg files are still there. It did clean up after the WebBuyingAssistant files though. The computer's working great so far but I would like to make sure I got everything of the virus out. Here's the HijackThis list:

BC AdBot (Login to Remove)

Welcome to the BleepingComputer HijackThis Logs and Analysis forum Josh98My name is Richie and i'll be helping you to fix your problems.

Download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktopClose any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply. Note: Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Do NOT post the ComboFix-quarantined-files.txt unless I ask.

First make sure all hidden files are showing:* Click 'Start'.* Open 'My Computer'.* Select the 'Tools' menu and click 'Folder Options'.* Select the 'View' tab.* Under the 'Hidden files and folders' heading select 'Show hidden files and folders'.* Uncheck the 'Hide file extensions for known types' option.* Uncheck the 'Hide protected operating system files (recommended)' option.* Click Yes to confirm.* Click OK.-------------------------------------------Your version of Sun Java is out of date.Older versions have vulnerabilities that malware can use to infect your system.Please follow these steps to remove older versions of Sun Java,and then update.1. Download the latest version of Java Runtime Environment (JRE)2. Scroll down to where it says 'Java Runtime Environment (JRE) 6u2'.3. Click the "Download" button to the right.4. Check the box that says: "Accept License Agreement".5. The page will refresh.6. Click on the link to download 'Windows Offline Installation, Multi-language' and save to your desktop.7. Close any programs you may have running - especially your web browser.8. Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.9. Check any item with Java Runtime Environment (JRE or J2SE) in the name.10. Click the Change/Remove button.11. Repeat as many times as necessary to remove each Java versions.12. Reboot your computer once all Java components are removed.13. Then from your desktop double-click on jre-6u2-windows-i586-p.exe to install the newest version.-------------------------------------------Download\install 'SuperAntiSpyware Home Edition Free Version' from here:http://www.superantispyware.com/downloadfi...ANTISPYWAREFREE

Launch SuperAntiSpyware and click on 'Check for updates'.Once the updates have been installed,exit SuperAntiSpyware.

Superantispyware will now scan your computer,when it's finished it will list all/any infections found.Make sure everything found has a checkmark next to it,then press 'Next'.Click on 'Finish' when you've done.

It's possible that the program will ask you to reboot in order to delete some files.

Obtain the SuperAntiSpyware log as follows:Click on 'Preferences'.Click on the 'Statistics/Logs' tab.Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.It will then open in your default text editor,such as Notepad.Copy and paste the contents of that report into your next reply.Also post a new Hijackthis log,let me know how your pc is running now.

wow, thought I only had 3 reg files to worry about! Antispy found over 150. Anyway, here's the new hijack and antispy logs. Oh one other thing......days ago doing this myself.....to fix the Webbuyingassistant I went into safe mode and deleted the main folder for it but there was a prefetch file that kept coming back whenever I rebooted so in safe mode in the allow/deny section of that file I denied wherever I could click deny. Will that be a problem?

Adware.Tracking Cookie C:\Documents and Settings\rick\Cookies\rick@tracking.foxnews[1].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[3].txt C:\Documents and Settings\rick\Cookies\rick@anad.tacoda[2].txt C:\Documents and Settings\rick\Cookies\rick@adknowledge[2].txt C:\Documents and Settings\rick\Cookies\rick@mediatraffic[1].txt C:\Documents and Settings\rick\Cookies\rick@bannerads[2].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[6].txt C:\Documents and Settings\rick\Cookies\rick@sitestat.mayoclinic[2].txt C:\Documents and Settings\rick\Cookies\rick@anat.tacoda[1].txt C:\Documents and Settings\rick\Cookies\rick@bannerads.zwire[1].txt C:\Documents and Settings\rick\Cookies\rick@40715998[2].txt C:\Documents and Settings\rick\Cookies\rick@kanoodle[2].txt C:\Documents and Settings\rick\Cookies\rick@offeroptimizer[1].txt C:\Documents and Settings\rick\Cookies\rick@atwola[1].txt C:\Documents and Settings\rick\Cookies\rick@sitestat.mayoclinic[1].txt C:\Documents and Settings\rick\Cookies\rick@cgi-bin[2].txt C:\Documents and Settings\rick\Cookies\rick@184908[1].txt C:\Documents and Settings\rick\Cookies\rick@icc.intellisrv[2].txt C:\Documents and Settings\rick\Cookies\rick@admarketplace[1].txt C:\Documents and Settings\rick\Cookies\rick@adv.webmd[1].txt C:\Documents and Settings\rick\Cookies\rick@sales.liveperson[3].txt C:\Documents and Settings\rick\Cookies\rick@cpvfeed[2].txt C:\Documents and Settings\rick\Cookies\rick@nextag[1].txt C:\Documents and Settings\rick\Cookies\rick@83748086[1].txt C:\Documents and Settings\rick\Cookies\rick@enhance[2].txt C:\Documents and Settings\rick\Cookies\rick@sales.liveperson[2].txt C:\Documents and Settings\rick\Cookies\rick@61755114[1].txt C:\Documents and Settings\rick\Cookies\rick@interclick[1].txt C:\Documents and Settings\rick\Cookies\rick@ads.monster[1].txt C:\Documents and Settings\rick\Cookies\rick@vhost.oddcast[2].txt C:\Documents and Settings\rick\Cookies\rick@cgi-bin[3].txt C:\Documents and Settings\rick\Cookies\rick@44183334[1].txt C:\Documents and Settings\rick\Cookies\rick@www.googleadservices[2].txt C:\Documents and Settings\rick\Cookies\rick@sources.sourcetool[1].txt C:\Documents and Settings\rick\Cookies\rick@adopt.specificclick[2].txt C:\Documents and Settings\alan\Cookies\alan@ads.cnn[2].txt C:\Documents and Settings\alan\Cookies\alan@ads.monster[2].txt C:\Documents and Settings\alan\Cookies\alan@cpvfeed[2].txt C:\Documents and Settings\alan\Cookies\alan@drivecleaner[2].txt C:\Documents and Settings\alan\Cookies\alan@m1.webstats4u[1].txt C:\Documents and Settings\alan\Cookies\alan@winantivirus[2].txt C:\Documents and Settings\angie\Cookies\angie@ads.adbrite[2].txt C:\Documents and Settings\angie\Cookies\angie@cpvfeed[2].txt C:\Documents and Settings\pat\Cookies\pat@a.websponsors[2].txt C:\Documents and Settings\pat\Cookies\pat@ad.musicmatch[1].txt C:\Documents and Settings\pat\Cookies\pat@ad1.clickhype[2].txt C:\Documents and Settings\pat\Cookies\pat@adecn[1].txt C:\Documents and Settings\pat\Cookies\pat@adknowledge[2].txt C:\Documents and Settings\pat\Cookies\pat@admarketplace[1].txt C:\Documents and Settings\pat\Cookies\pat@adopt.specificclick[1].txt C:\Documents and Settings\pat\Cookies\pat@adprofile[1].txt C:\Documents and Settings\pat\Cookies\pat@ads.addesktop[1].txt C:\Documents and Settings\pat\Cookies\pat@ads.auctionads[1].txt C:\Documents and Settings\pat\Cookies\pat@ads.cnn[1].txt C:\Documents and Settings\pat\Cookies\pat@ads.glispa[2].txt C:\Documents and Settings\pat\Cookies\pat@ads.monster[1].txt C:\Documents and Settings\pat\Cookies\pat@anad.tacoda[2].txt C:\Documents and Settings\pat\Cookies\pat@anat.tacoda[1].txt C:\Documents and Settings\pat\Cookies\pat@atwola[1].txt C:\Documents and Settings\pat\Cookies\pat@automedia[1].txt C:\Documents and Settings\pat\Cookies\pat@banners.nbcupromotes[1].txt C:\Documents and Settings\pat\Cookies\pat@belnk[1].txt C:\Documents and Settings\pat\Cookies\pat@burstnet[2].txt C:\Documents and Settings\pat\Cookies\pat@campaign.indieclick[1].txt C:\Documents and Settings\pat\Cookies\pat@clicks.emarketmakers[1].txt C:\Documents and Settings\pat\Cookies\pat@clicktorrent[1].txt C:\Documents and Settings\pat\Cookies\pat@cpvfeed[2].txt C:\Documents and Settings\pat\Cookies\pat@data4.perf.overture[2].txt C:\Documents and Settings\pat\Cookies\pat@dist.belnk[2].txt C:\Documents and Settings\pat\Cookies\pat@icc.intellisrv[2].txt C:\Documents and Settings\pat\Cookies\pat@kanoodle[1].txt C:\Documents and Settings\pat\Cookies\pat@lynxtrack[1].txt C:\Documents and Settings\pat\Cookies\pat@medianewsgroup[2].txt C:\Documents and Settings\pat\Cookies\pat@mediatraffic[2].txt C:\Documents and Settings\pat\Cookies\pat@monstersandcritics.advertserve[1].txt C:\Documents and Settings\pat\Cookies\pat@nextag[1].txt C:\Documents and Settings\pat\Cookies\pat@pagetrack.iomega[2].txt C:\Documents and Settings\pat\Cookies\pat@partner2profit[2].txt C:\Documents and Settings\pat\Cookies\pat@precisionclick[1].txt C:\Documents and Settings\pat\Cookies\pat@precisionclick[3].txt C:\Documents and Settings\pat\Cookies\pat@qnsr[2].txt C:\Documents and Settings\pat\Cookies\pat@rp.adprofile[2].txt C:\Documents and Settings\pat\Cookies\pat@sales.liveperson[1].txt C:\Documents and Settings\pat\Cookies\pat@sales.liveperson[2].txt C:\Documents and Settings\pat\Cookies\pat@sales.liveperson[3].txt C:\Documents and Settings\pat\Cookies\pat@sec1.liveperson[1].txt C:\Documents and Settings\pat\Cookies\pat@spamblockerutility[1].txt C:\Documents and Settings\pat\Cookies\pat@tracking.foxnews[2].txt C:\Documents and Settings\pat\Cookies\pat@vhost.oddcast[2].txt C:\Documents and Settings\pat\Cookies\pat@wTracker[2].txt C:\Documents and Settings\pat\Cookies\pat@www.burstbeacon[2].txt C:\Documents and Settings\pat\Cookies\pat@www.dealtime[2].txt C:\Documents and Settings\pat\Cookies\pat@yieldmanager[1].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[1].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[2].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[4].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[5].txt C:\Documents and Settings\rick\Cookies\rick@azjmp[6].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[1].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[2].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[3].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[4].txt C:\Documents and Settings\rick\Cookies\rick@h.starware[5].txt

Computer's running fine now btw......just remembered you asked how it ran along with the logs. sorry! But the webbuy prefetch file is still there even though I denied it access which I mentioned in my previous post.

Double-click ATF-Cleaner.exe to run the program.Click 'Select All' found at the bottom of the list.Click the 'Empty Selected' button.

If you use Firefox browser, do this also:Click Firefox at the top and choose 'Select All' from the list.Click the 'Empty Selected' button.NOTE:If you would like to keep your saved passwords,please click 'No' at the prompt.

If you use Opera browser,do this also:Click Opera at the top and choose 'Select All' from the list.Click the 'Empty Selected' button.NOTE:If you would like to keep your saved passwords,please click 'No' at the prompt.

Click 'Exit' on the Main menu to close the program.------------------------------------------------------------------Download and scan with the free 15 day trial of Counterspy V2Save the report when it's finished:1.Once Counterspy has done scanning,the 'Scan Results' box will appear.2.Click on 'View Results'.3.Under (Recommended Action),using the drop down menus at the side of each entry found,set EVERYTHING to 'Remove'.4.Then click on 'Take Action'.5.Once everything has been removed,click on 'View Details'.6.Copy and Paste those details into your next reply.

Also post a new Hijackthis log.Let me know how your pc is running now.

Still running smooth...I don't see any sign of the prefetch file I was talking about. I'll do a scan with spybot and see if the reg files come up. Instead of 3 last time there were two.....I'll post that in a minute. For now here's the counterspy and hijackthis list:

Virtumonde Adware (General) more information...Details: Virtumonde is an adware program that displays pop-up advertisements on the desktop. Virtumonde also downloads other software from various remote servers.Status: Deleted

Files detectedC:\QooBox\Quarantine\C\WINDOWS\system32\nnnkiif.dll.vir

Trojan-Downloader.Gen Trojan Downloader more information...Details: Trojan-Downloader.Gen is a group of Trojan Downloaders which install download and install multiple unwanted applications of adware and malware from remote servers.Status: Deleted

Click on Start/All Programs/Accessories/System Tools/System Restore. In the 'System Restore' window,click on the 'Create a Restore Point' button,then click 'Next'. In the window that appears,enter a description\name for the Restore Point,then click on 'Create',wait,then click 'Close'. The date and time will be created automatically.

Next click on Start/All Programs/Accessories/System Tools/Disk Cleanup.The 'Select Drive' box will appear,click on Ok.The 'Disk Cleanup for [C:]' box will appear,click on the 'More Options' tab.At the bottom in the 'System Restore' window,click on the 'Clean up...' button.A box will pop up 'Are you sure you want to delete all but the most recent restore point?',click on 'Yes'.Click on 'Yes' at 'Are you sure you want to perform these actions?'.Now wait until 'Disk Cleanup' finishes and the box disappears.

Hey Richie.......thanks so much for all your help with this! I PROMISE to send you some money for helping me out when I get my next check. If you don't mind (you're going to be mad) would you mind taking a look at my logs one more time??? Yesterday I noticed combofix took a file from the F:drive of my computer called autorun.ini that I thought went to help display a graphic that wasn't there anymore in My Computer. Stupidly I took the file out of quarentine and put back on the f:drive just to find out on the next bootup there was still no graphic and running superantispy found 3 files. I didn't connect to the internet or anything it was just to see if it worked on that file of autorun with the graphic on that drive. I placed that file back in quarentine with the .vir extension rebooted and did another scan with superantispy that didn't bring up anything. Spybot brought up around 25 cookies but no files. Vundofix didn't find anything either. Again I'm so sorry for the trouble.....

Clear your 'System Restore' points by doing the following: Right-click on 'My Computer' and select 'Properties'. Select 'System Restore'. Select 'Turn Off System Restore On All Drives'. Select 'Apply'. You will then get the following warning:"You have chosen to turn off System Restore.If you continue,all existing restore points will be deleted,and you will not be able to track or undo changes to your computer.Do you want to turn off System Restore?".Then select 'Yes',your 'System Restore' directories will be purged.

Download Combofix and save to your desktop:Note: It is important that it is saved directly to your desktopClose any open browsers. Double click on combofix.exe and follow the prompts. When it's finished it will produce a log. Post the entire contents of C:\ComboFix.txt into your next reply.Note: Do not mouseclick combofix's window while it's running. That may cause the program to freeze/hang. Do NOT post the ComboFix-quarantined-files.txt unless I ask.

Thanks Richie you're the man! 1000 blessings on you and your family! One last thing before I go.....would you want me to delete combofix and the qoobox still as you mentioned in a previous post before I f-ed it up again???? And re-show all the hidden files and folders?